Technique ID,Detection Available,Link,score T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 T1055.011,No,-,0 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/scheduled_task_deleted_or_created_via_cmd.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_scheduling_job_on_remote_system.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_used_for_forcing_a_reboot.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_scheduled_task_from_public_directory.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml,7 T1053.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winevent_scheduled_task_created_within_public_path.yml,7 T1066,No,-,0 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/7zip_commandline_to_smb_share_path.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/anomalous_usage_of_7zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_7_zip.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_winrar.yml,5 T1560.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icedid_exfiltrated_archived_file_creation.yml,5 T1021.005,No,-,0 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_process_instantiation_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/remote_wmi_command_attempt.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/script_execution_via_wmi.yml,5 T1047,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,5 T1156,No,-,0 T1113,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1067,No,-,0 T1037,No,-,0 T1557,No,-,0 T1033,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_taskhost_processes.yml,1 T1583,No,-,0 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___advpack.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___setupapi.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_application_control_bypass___syssetup.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_dnsquery.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_lockworkstation.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_process_creating_exe_dll_files.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_with_no_command_line_arguments_with_network.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll_loading_dll_by_ordinal.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_rundll32_cmdline.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_dllregisterserver.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_plugininit.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_startw.yml,14 T1218.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml,14 T1613,No,-,0 T1143,No,-,0 T1161,No,-,0 T1132.001,No,-,0 T1150,No,-,0 T1556.003,No,-,0 T1578.004,No,-,0 T1148,No,-,0 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_avproduct_through_pwh_or_wmi.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recon_using_wmi_class.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml,7 T1592,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_recon_running_process_or_services.yml,7 T1596.003,No,-,0 T1056.001,No,-,0 T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_dsinternals_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_mimikatz_modules.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml,37 T1003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_powersploit_modules.yml,37 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 T1498.001,No,-,0 T1492,No,-,0 T1574.007,No,-,0 T1213.002,No,-,0 T1006,No,-,0 T1044,No,-,0 T1491.002,No,-,0 T1171,No,-,0 T1590.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml,1 T1499.001,No,-,0 T1014,No,-,0 T1546.013,No,-,0 T1059.007,No,-,0 T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_ransomware_known_service_name.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,10 T1543,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_process_file_path.yml,10 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 T1539,No,-,0 T1053.007,No,-,0 T1568.002,No,-,0 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_remote_user_account_control.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/eventvwr_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/net_profiler_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sdclt_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/silentcleanup_uac_bypass.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_runas_elevated.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/slui_spawning_a_process.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_mmc_load_unsigned_dll.yml,10 T1548.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wsreset_uac_bypass.yml,10 T1099,No,-,0 T1016.001,No,-,0 T1548.003,No,-,0 T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,11 T1114,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_pst_export_alert.yml,5 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_powershell.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excel_spawning_windows_script_host.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/extract_sam_from_registry.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_deleting_its_process_file_path.yml,7 T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sam_database_file_access_attempt.yml,7 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 T1069.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,1 T1574.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml,1 T1596.001,No,-,0 T1499.003,No,-,0 T1163,No,-,0 T1195.001,No,-,0 T1588.004,No,-,0 T1583.002,No,-,0 T1561,No,-,0 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,2 T1071.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/dns_record_changed.yml,2 T1552.005,No,-,0 T1555.002,No,-,0 T1542.003,No,-,0 T1025,No,-,0 T1116,No,-,0 T1522,No,-,0 T1093,No,-,0 T1074.001,No,-,0 T1036.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,1 T1172,No,-,0 T1587.003,No,-,0 T1565.001,No,-,0 T1110.002,No,-,0 T1178,No,-,0 T1114.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mailsniper_invoke_functions.yml,1 T1555.001,No,-,0 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,12 T1547,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,12 T1003.004,No,-,0 T1013,No,-,0 T1600,No,-,0 T1606.002,No,-,0 T1192,No,-,0 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_service_stop_attempt.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___delete_a_net_user.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_delete_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___attempt_to_disable_services.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___disable_net_user_account.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___resize_shadowstorage_volume.yml,8 T1489,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_security_account_manager_stopped.yml,8 T1587.001,No,-,0 T1121,No,-,0 T1206,No,-,0 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/account_discovery_with_net_app.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,6 T1087.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,6 T1547.014,No,-,0 T1564,No,-,2 T1559.002,No,-,0 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/uncommon_processes_on_endpoint.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/batch_file_write_to_system32.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/drop_icedid_license_dat.yml,4 T1204.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/single_letter_process_on_endpoint.yml,4 T1591.003,No,-,0 T1063,No,-,0 T1592.001,No,-,0 T1080,No,-,0 T1484.002,No,-,0 T1573.001,No,-,0 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1087.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1167,No,-,0 T1586.001,No,-,0 T1527,No,-,0 T1180,No,-,0 T1542.005,No,-,0 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sc_exe_manipulating_windows_services.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_driver_loaded_path.yml,4 T1543.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/xmrig_driver_loaded.yml,4 T1568.001,No,-,0 T1497.001,No,-,0 T1053.003,No,-,0 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1588.006,No,-,0 T1566.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_creating_lnk_file_in_suspicious_location.yml,1 T1165,No,-,0 T1070.002,No,-,0 T1499.004,No,-,0 T1137,No,-,0 T1218.004,No,-,0 T1598.003,No,-,0 T1021.004,No,-,0 T1098.003,No,-,0 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_adding_a_printer_driver.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/print_spooler_failed_to_load_a_plug_in.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_spawning_rundll32.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_loaded_modules.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll.yml,6 T1547.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_writing_a_dll___sysmon.yml,6 T1089,No,-,0 T1487,No,-,0 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_email_suspicious_attachment.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_regsvr32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_application_spawn_rundll32_process.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_creating_schedule_task.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_executing_macro_code.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_document_spawned_child_process_to_download.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_bitsadmin.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_certutil.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_mshta.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_rundll32_with_no_dll.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawning_wmic.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_cmd.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_powershell.yml,14 T1566.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/winword_spawning_windows_script_host.yml,14 T1214,No,-,0 T1559.001,No,-,0 T1574.001,No,-,0 T1119,No,-,0 T1115,No,-,0 T1003.007,No,-,0 T1583.005,No,-,0 T1555.005,No,-,0 T1103,No,-,0 T1553.001,No,-,0 T1608.004,No,-,0 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1040,No,-,0 T1017,No,-,0 T1553.002,No,-,0 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets.yml,2 T1530,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_new_open_s3_buckets_over_aws_cli.yml,2 T1565.003,No,-,0 T1552.002,No,-,0 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1135,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1120,No,-,0 T1590.004,No,-,0 T1587.002,No,-,0 T1222.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.006,No,-,0 T1505.002,No,-,0 T1082,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_information_discovery_detection.yml,1 T1071,No,-,3 T1074.002,No,-,0 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_http_command_arguments.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schedule_task_with_rundll32_command_trigger.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/schtasks_run_task_on_demand.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,14 T1053,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,14 T1218.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uninstall_app_using_msiexec.yml,1 T1162,No,-,0 T1590.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1498.002,No,-,0 T1556.002,No,-,0 T1059.002,No,-,0 T1176,No,-,0 T1499.002,No,-,0 T1195.003,No,-,0 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,2 T1106,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,2 T1558.004,No,-,0 T1058,No,-,0 T1584.003,No,-,0 T1600.001,No,-,0 T1070.003,No,-,0 T1202,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/sqlite_module_in_temp_folder.yml,1 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_with_decode_argument.yml,2 T1140,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_using_memory_as_backing_store.yml,2 T1137.005,No,-,0 T1562,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unloading_amsi_via_reflection.yml,31 T1586.002,No,-,0 T1608.001,No,-,0 T1195,No,-,0 T1190,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unified_messaging_service_spawning_a_process.yml,1 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1558,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,3 T1555,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___credential_extraction_lazagne_command_options.yml,3 T1567,No,-,1 T1219,No,-,0 T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 T1036,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_writes_to_system_volume_information.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/executables_or_script_creation_in_suspicious_path.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___system_process_running_unexpected_location.yml,12 T1036,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_writes_to_windows_recycle_bin.yml,12 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/shim_database_installation_with_suspicious_parameters.yml,3 T1552,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1547.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/monitor_registry_keys_for_print_monitors.yml,1 T1037.002,No,-,0 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cobalt_strike_named_pipes.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_in_shell_application.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dllhost_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_remote_thread_to_known_windows_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_create_remote_thread_to_a_process.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/rundll32_createremotethread_in_browser.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/searchprotocolhost_with_no_command_line_with_network.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_dllhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_gpupdate_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml,18 T1055,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/trickbot_named_pipe.yml,18 T1139,No,-,0 T1205,No,-,0 T1503,No,-,0 T1218,No,-,39 T1153,No,-,0 T1038,No,-,0 T1050,No,-,0 T1070.006,No,-,0 T1611,No,-,0 T1547.009,No,-,0 T1010,No,-,0 T1032,No,-,0 T1087.003,No,-,0 T1062,No,-,0 T1497.003,No,-,0 T1182,No,-,0 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmlua_or_cmstplua_uac_bypass.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/uac_bypass_with_colorui_com_object.yml,3 T1218.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbemprox_com_object_execution.yml,3 T1563.001,No,-,0 T1562.002,No,-,0 T1029,No,-,0 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_psexec_with_accepteula_flag.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,5 T1021.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/write_executable_in_smb_share.yml,5 T1525,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_gcr_container_uploaded.yml,1 T1572,No,-,0 T1218.002,No,-,0 T1599.001,No,-,0 T1608.002,No,-,0 T1547.005,No,-,0 T1004,No,-,0 T1009,No,-,0 T1550,No,-,2 T1076,No,-,0 T1597.001,No,-,0 T1011,No,-,0 T1602.002,No,-,0 T1589,No,-,1 T1131,No,-,0 T1181,No,-,0 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/processes_created_by_netsh.yml,2 T1562.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/processes_launching_netsh.yml,2 T1560,No,-,5 T1152,No,-,0 T1553.003,No,-,0 T1483,No,-,0 T1185,No,-,0 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enable_rdp_in_other_port_number.yml,9 T1021,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,9 T1071.003,No,-,0 T1595.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,1 T1596,No,-,0 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,2 T1207,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,2 T1553.006,No,-,0 T1610,No,-,0 T1107,No,-,0 T1145,No,-,0 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fodhelper_uac_bypass.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_registry_entry.yml,3 T1112,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_reg_exe_process.yml,3 T1543.004,No,-,0 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_accessdenied_discovery_events.yml,2 T1580,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,2 T1555.003,No,-,0 T1574.008,No,-,0 T1491,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modification_of_wallpaper.yml,1 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_aws_console_login_by_user_from_new_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_in_previously_unseen_region.yml,8 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_exchange_web_shell.yml,2 T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 T1583.004,No,-,0 T1021.006,No,-,0 T1011.001,No,-,0 T1078.001,No,-,0 T1547.003,No,-,0 T1183,No,-,0 T1085,No,-,0 T1031,No,-,0 T1546.005,No,-,0 T1574.006,No,-,0 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_new_local_admin_account.yml,3 T1136.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/short_lived_windows_accounts.yml,3 T1092,No,-,0 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_logs_using_wevtutil.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_clear_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___wevtutil_usage_to_disable_logs.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_event_log_service_behavior.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_wevtutil_usage.yml,6 T1070.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_event_log_cleared.yml,6 T1585.002,No,-,0 T1557.001,No,-,0 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_cacls_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_deny_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/icacls_grant_command.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/modify_acl_permission_to_files_or_folder.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/permission_modification_using_takeown_app.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___deny_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___grant_permission_using_cacls_utility.yml,9 T1222,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___modify_acls_permission_of_files_or_folders.yml,9 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/unsigned_image_loaded_by_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/access_lsass_memory_for_dump_creation.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_remote_thread_into_lsass.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_lsass_dump_with_taskmgr.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_credential_dumping_through_lsass_access.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mimikatz_using_loaded_images.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_comsvcs_dll.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump.yml,10 T1003.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dump_lsass_via_procdump_rename.yml,10 T1053.001,No,-,0 T1179,No,-,0 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attacker_tools_on_endpoint.yml,3 T1595,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,3 T1547.011,No,-,0 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_operation_with_consent_admin.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/services_escalate_exe.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,16 T1548,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,16 T1134.002,No,-,0 T1548.001,No,-,0 T1547.004,No,-,0 T1019,No,-,0 T1021.003,No,-,0 T1042,No,-,0 T1117,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,1 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_failing_to_authenticate_from_process.yml,8 T1110.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml,8 T1090.002,No,-,0 T1056.003,No,-,0 T1589.002,No,-,0 T1164,No,-,0 T1054,No,-,0 T1108,No,-,0 T1193,No,-,0 T1003.005,No,-,0 T1098.004,No,-,0 T1215,No,-,0 T1101,No,-,0 T1590.006,No,-,0 T1546.012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_privilege_escalation.yml,1 T1218.008,No,-,0 T1593.002,No,-,0 T1177,No,-,0 T1591.002,No,-,0 T1125,No,-,0 T1144,No,-,0 T1045,No,-,0 T1055.013,No,-,0 T1016,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml,1 T1578.003,No,-,0 T1574.005,No,-,0 T1546.008,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/overwriting_accessibility_binaries.yml,1 T1504,No,-,0 T1198,No,-,0 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/enumerate_users_local_group_using_telegram.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,16 T1087,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,16 T1090,No,-,0 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/chcp_command_execution.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___first_time_seen_cmd_line.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml,29 T1059,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml,29 T1562.006,No,-,0 T1136.002,No,-,0 T1589.003,No,-,0 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dsquery_domain_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nltest_domain_trust_discovery.yml,8 T1482,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,8 T1558.001,No,-,0 T1175,No,-,0 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rclone_command_line_usage.yml,2 T1020,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_rclone.yml,2 T1592.004,No,-,0 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_created_with_all_open_ports.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_network_access_control_list_deleted.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_bypass_mfa_via_trusted_ip.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_network_acl_activity.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_file_and_printing_sharing_in_firewall.yml,6 T1562.007,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_network_discovery_in_firewall.yml,6 T1036.002,No,-,0 T1588.001,No,-,0 T1542.002,No,-,0 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/fsutil_zeroing_file.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml,12 T1070,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/usn_journal_deletion.yml,12 T1048.001,No,-,0 T1137.001,No,-,0 T1583.003,No,-,0 T1213.001,No,-,0 T1550.003,No,-,0 T1609,No,-,0 T1083,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1568,No,-,0 T1036.004,No,-,0 T1055.004,No,-,0 T1020.001,No,-,0 T1138,No,-,0 T1546.009,No,-,0 T1191,No,-,0 T1188,No,-,0 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_admin_email_forwarding.yml,2 T1114.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_user_email_forwarding.yml,2 T1074,No,-,0 T1049,No,-,0 T1584,No,-,0 T1553.005,No,-,0 T1600.002,No,-,0 T1542,No,-,0 T1064,No,-,0 T1612,No,-,0 T1051,No,-,0 T1055.002,No,-,0 T1218.012,No,-,0 T1586,No,-,0 T1569.001,No,-,0 T1584.005,No,-,0 T1059.008,No,-,0 T1552.003,No,-,0 T1497,No,-,0 T1102,No,-,0 T1552.001,No,-,0 T1568.003,No,-,0 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_renamed.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_mshta_url_in_command_line.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_rundll32_inline_hta_execution.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/office_product_spawn_cmd_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_child_process.yml,8 T1218.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_mshta_spawn.yml,8 T1608,No,-,0 T1608.005,No,-,0 T1104,No,-,0 T1480,No,-,0 T1606.001,No,-,0 T1134.001,No,-,0 T1567.001,No,-,0 T1205.001,No,-,0 T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clop_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/conti_common_exec_parameter.yml,12 T1204,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/revil_common_exec_parameter.yml,12 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 T1552.006,No,-,0 T1196,No,-,0 T1048.002,No,-,0 T1087.004,No,-,0 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1057,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1562.003,No,-,0 T1053.004,No,-,0 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_wmi_event_subscription_persistence.yml,2 T1546.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wmi_permanent_event_subscription___sysmon.yml,2 T1596.004,No,-,0 T1497.002,No,-,0 T1141,No,-,0 T1072,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1041,No,-,0 T1134.004,No,-,0 T1591,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1060,No,-,0 T1606,No,-,0 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,2 T1554,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,2 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadfile.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/any_powershell_downloadstring.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_empire_with_powershell_script_block_logging.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___execution_policy_bypass.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/nishang_powershelltcponeline.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_domain_enumeration.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_processing_stream_of_data.yml,15 T1059.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,15 T1023,No,-,0 T1546.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_changes_to_file_associations.yml,1 T1055.014,No,-,0 T1026,No,-,0 T1071.002,No,-,0 T1122,No,-,0 T1015,No,-,0 T1212,No,-,0 T1546.014,No,-,0 T1102.003,No,-,0 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,5 T1590,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml,5 T1210,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_computer_changed_with_anonymous_account.yml,1 T1502,No,-,0 T1142,No,-,0 T1534,No,-,0 T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/registry_keys_used_for_persistence.yml,2 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/start_up_during_safe_mode_boot.yml,2 T1199,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createaccesskey.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_createloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_updateloginprofile.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_add_app_role_assignment_grant_user.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_added_service_principal.yml,6 T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_new_federated_domain_added.yml,6 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_azurehound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_command_line_arguments.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_file_modifications.yml,5 T1069.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_sharphound_usage.yml,5 T1149,No,-,0 T1593,No,-,0 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_delete_policy.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_failure_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_successful_group_deletion.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,15 T1098,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,15 T1170,No,-,0 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/dns_exfiltration_using_nslookup_app.yml,9 T1048,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_nslookup_app.yml,9 T1547.006,No,-,0 T1056.002,No,-,0 T1097,No,-,0 T1588.002,No,-,0 T1052.001,No,-,0 T1597,No,-,0 T1053.006,No,-,0 T1566,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/suspicious_email___uba_anomaly.yml,17 T1061,No,-,0 T1542.004,No,-,0 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_renamed.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_spawn_child_process.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_url_in_command_line.yml,4 T1218.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_html_help_using_infotech_storage_handlers.yml,4 T1070.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_or_delete_windows_shares_using_net_exe.yml,1 T1090.003,No,-,0 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_iam_assume_role_policy_brute_force.yml,10 T1110,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_authentication_failures_alert.yml,10 T1059.004,No,-,0 T1137.003,No,-,0 T1157,No,-,0 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_stop_security_service.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_amsi_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_etw_through_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_registry_tool.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_app_hotkeys.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_behavior_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_windows_smartscreen_protection.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_cmd_application.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_controlpanel.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_firewall_with_netsh.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_folderoptions_windows_feature.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_norun_windows_app.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_systemrestore_in_registry.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_task_manager.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_number_of_service_control_start_as_disabled.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_taskkill.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/hide_user_account_from_sign_in_screen.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_disable_security_monitoring.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/process_kill_base_on_file_path.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/unload_sysmon_filter_driver.yml,22 T1562.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/windows_disableantispyware_reg.yml,22 T1565,No,-,0 T1559,No,-,0 T1001,No,-,0 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml,3 T1039,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml,3 T1584.006,No,-,0 T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 T1574,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_creating_thread_mutex.yml,2 T1027.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_enable_smb1protocol_feature.yml,2 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_high.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_scanning_findings_medium.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_outside_business_hours.yml,5 T1204.003,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_ecr_container_upload_unknown_user.yml,5 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_access_by_provider_user_and_principal.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_saml_update_identity_provider.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_city.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_country.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_provisioning_from_previously_unseen_region.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_detect_oauth_token_abuse.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___anomalous_user_clickspeed.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,44 T1078,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 T1055.012,No,-,0 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/first_time_seen_child_process_of_zoom.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/spoolsv_suspicious_process_access.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml,10 T1068,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___setting_credentials_via_powersploit_modules.yml,10 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_of_net_users.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disabling_net_user_account.yml,3 T1531,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_net_app.yml,3 T1110.004,No,-,0 T1208,No,-,0 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_process___encoded_command.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml,5 T1027,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wermgr_process_create_executable_file.yml,5 T1114.002,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_suspicious_rights_delegation.yml,1 T1036.001,No,-,0 T1564.006,No,-,0 T1154,No,-,0 T1201,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml,1 T1546,No,-,9 T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_process_termination_frequency.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ransomware_notes_bulk_creation.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_test_files_detected.yml,6 T1486,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 T1592.003,No,-,0 T1573,No,-,0 T1174,No,-,0 T1547.002,No,-,0 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvr32_application_control_bypass.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_icedid_regsvr32_cmdline.yml,3 T1218.010,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_regsvr32_register_suspicious_path.yml,3 T1002,No,-,0 T1081,No,-,0 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1592.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml,2 T1128,No,-,0 T1056,No,-,0 T1587.004,No,-,0 T1593.001,No,-,0 T1546.015,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_execute_com_object.yml,1 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/execution_of_file_with_spaces_before_extension.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execution_of_file_with_multiple_extensions.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_rundll32_rename.yml,7 T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 T1573.002,No,-,0 T1567.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_drive_share_in_external_email.yml,1 T1570,No,-,0 T1574.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_path_interception_by_creation_of_program_exe.yml,1 T1608.003,No,-,0 T1168,No,-,0 T1166,No,-,0 T1037.005,No,-,0 T1100,No,-,0 T1186,No,-,0 T1184,No,-,0 T1095,No,-,0 T1075,No,-,0 T1027.003,No,-,0 T1584.002,No,-,0 T1001.003,No,-,0 T1012,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1030,No,-,0 T1028,No,-,0 T1550.004,No,-,0 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/identify_new_user_accounts.yml,2 T1078.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_account_lockouts_from_endpoint.yml,2 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regasm_with_no_command_line_arguments.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_spawning_a_process.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_network_connection.yml,6 T1218.009,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_regsvcs_with_no_command_line_arguments.yml,6 T1034,No,-,0 T1506,No,-,0 T1553.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.003,No,-,0 T1499,No,-,0 T1027.004,No,-,0 T1065,No,-,0 T1614,No,-,0 T1564.007,No,-,0 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bits_job_persistence.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,3 T1197,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/powershell_start_bitstransfer.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_path.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_rename.yml,3 T1127.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_msbuild_spawn.yml,3 T1088,No,-,0 T1494,No,-,0 T1090.004,No,-,0 T1557.002,No,-,0 T1562.008,No,-,0 T1518.001,No,-,0 T1564.003,No,-,0 T1493,No,-,0 T1059.006,No,-,0 T1591.004,No,-,0 T1132,No,-,0 T1546.010,No,-,0 T1598,No,-,0 T1496,No,-,0 T1585,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml,1 T1588,No,-,0 T1546.002,No,-,0 T1147,No,-,0 T1578.002,No,-,0 T1500,No,-,0 T1565.002,No,-,0 T1003.008,No,-,0 T1543.001,No,-,0 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml,6 T1569,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/first_time_seen_command_line_argument.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/windows_connhost_exe_force_flag.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/cmd_echo_pipe___escalation.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,6 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ryuk_wake_on_lan_command.yml,6 T1055.009,No,-,0 T1223,No,-,0 T1601.001,No,-,0 T1558.002,No,-,0 T1213,No,-,0 T1146,No,-,0 T1555.004,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 T1505,No,-,2 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_extensions.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/common_ransomware_notes.yml,3 T1485,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,Yes,https://github.com/splunk/security_content/blob/develop/cloud/detect_shared_ec2_snapshot.yml,1 T1130,No,-,0 T1022,No,-,0 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/clear_unallocated_sector_using_cipher_app.yml,2 T1070.004,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/recursive_delete_of_directory_in_batch_cmd.yml,2 T1189,Yes,https://github.com/splunk/security_content/blob/develop/network/detect_hosts_connecting_to_dynamic_domain_providers.yml,1 T1498,No,-,0 T1595.001,No,-,0 T1158,No,-,0 T1221,No,-,0 T1037.004,No,-,0 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,4 T1134,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,4 T1209,No,-,0 T1111,No,-,0 T1159,No,-,0 T1027.002,No,-,0 T1071.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml,1 T1059.005,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/execute_javascript_with_jscript_com_clsid.yml,1 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 T1136,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/web_fraud___account_harvesting.yml,10 T1547.013,No,-,0 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_excessive_security_scanning.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/gcp_kubernetes_cluster_scan_detection.yml,3 T1526,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/kubernetes_azure_scan_fingerprint.yml,3 T1151,No,-,0 T1018,No,-,0 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,2 T1046,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml,2 T1590.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1518,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml,1 T1538,No,-,0 T1055.005,No,-,0 T1036.006,No,-,0 T1547.007,No,-,0 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml,2 T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/msmpeng_application_dll_side_loading.yml,1 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bitsadmin_download_file.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_urlcache_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml,4 T1105,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/download_files_using_telegram.yml,4 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 T1084,No,-,0 T1160,No,-,0 T1055.008,No,-,0 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml,2 T1021.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/allow_inbound_traffic_in_firewall_rule.yml,2 T1037.001,No,-,0 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,4 T1484,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,4 T1220,No,-,0 T1596.005,No,-,0 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml,2 T1564.001,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/disable_show_hidden_files.yml,2 T1578.001,No,-,0 T1591.001,No,-,0 T1137.002,No,-,0 T1587,No,-,0 T1173,No,-,0 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ntdsutil_export_ntds.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/secretdumps_offline_ntds_dumping_tool.yml,7 T1003.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml,7 T1602.001,No,-,0 T1001.002,No,-,0 T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/create_service_in_suspicious_file_path.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_renamed_psexec.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/excessive_usage_of_sc_service_utility.yml,4 T1569.002,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/malicious_powershell_executed_as_a_service.yml,4 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_create_policy_version_to_allow_all_resources.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/aws_setdefaultpolicyversion.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/cloud/cloud_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_api_calls_from_user_roles.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_new_user_aws_console_login.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_aws_api_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_spike_in_security_group_activity.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_modified_with_previously_unseen_user.yml,17 T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1558.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___detect_kerberoasting.yml,2 T1096,No,-,0 T1003.006,No,-,0 T1124,No,-,0 T1053.002,No,-,0 T1035,No,-,0 T1055.001,No,-,0 T1086,No,-,0 T1588.005,No,-,0 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_disable_mfa.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/cloud/o365_excessive_sso_logon_errors.yml,3 T1556,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/bcdedit_failure_recovery_modification.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/delete_shadowcopy_with_powershell.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/deleting_shadow_copies.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/known_services_killed_by_ransomware.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/resize_shadowstorage_volume.yml,7 T1490,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/wbadmin_delete_system_backups.yml,7 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 T1216,No,-,0 T1094,No,-,0 T1102.001,No,-,0 T1118,No,-,0 T1001.001,No,-,0 T1598.001,No,-,0 T1043,No,-,0 T1552.007,No,-,0 T1584.001,No,-,0 T1505.001,No,-,0 T1556.004,No,-,0 T1561.001,No,-,0 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/clients_connecting_to_multiple_dns_servers.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detect_long_dns_txt_record_response.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/deprecated/detection_of_dns_tunnels.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/gsuite_outbound_email_with_attachment_to_external_domain.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/dns_query_length_with_high_standard_deviation.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/multiple_archive_files_http_post_traffic.yml,7 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/network/plain_http_post_exfiltrated_data.yml,7 T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_rename.yml,5 T1127,Yes,https://github.com/splunk/security_content/blob/develop/endpoint/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0